Skip to content

Abyss

Abyss is a ransomware threat associated with intrusions in which attackers maintain long-term access through compromised edge appliances, particularly SonicWall Secure Mobile Access devices.

Profile source: Mallory opens in a new tab

Abyss

Family profile

Abyss is a ransomware threat associated with intrusions in which attackers maintain long-term access through compromised edge appliances, particularly SonicWall Secure Mobile Access devices. Documented incidents show initial access obtained by exploiting CVE-2021-20039 on SonicWall SMA systems, followed by installation of a persistent web shell on the appliance. In at least one investigated case, operators later deployed a SOCKS proxy on the compromised device and tunneled RDP traffic into the internal network, allowing them to move from the edge appliance into the victim environment while minimizing the need to place additional malware on internal hosts. This tradecraft reduced opportunities for endpoint detection and enabled the intrusion to remain unnoticed for an extended period before ransomware encryption was executed.

Abyss activity has been observed in incidents involving prolonged dwell time, persistence on internet-facing infrastructure, and post-compromise use of legitimate remote access protocols. Reporting has also noted overlaps between Abyss-related ransomware incidents and later SonicWall SMA compromise activity involving other malware families, indicating recurring attacker interest in vulnerable or poorly monitored remote access appliances as a foothold. Manufacturing and other industrial environments appear in broader ransomware tracking that includes Abyss among less frequently observed groups, but publicly available information in the supplied material is limited regarding a distinct victimology pattern, internal encryption mechanics, or a formal ransomware-as-a-service structure.

High-confidence characteristics supported here are that Abyss is used as ransomware, that it has been deployed after exploitation of vulnerable edge devices, and that associated operators used persistence and post-exploitation access through compromised SMA appliances to facilitate the eventual attack.

Capabilities

  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation

Operational record

1
YARA rules
1
Leak sites
1 available

Exploited software

Vulnerabilities linked to Abyss

1 CVEs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.